Capto 2.0.5 · Privacy

Local first.
No hidden cloud.

Desktop app. No account. Captured pixels stay local unless you share them. Translation, update checks, and uncached OCR assets are the named network paths below.

What never leaves.

Captures, recordings, Library entries, OCR results, and settings stay on this machine unless you move them.

  • No account and no sign-in
  • No telemetry or crash reporter
  • Tesseract runs on your CPU
  • Keys stay under Windows DPAPI

What can use the network.

Every path is explicit: actions you invoke, release checks, and uncached OCR assets.

  • User-invoked share to your own bucket
  • User-invoked translation through your provider
  • Signed update checks at startup and every 30 minutes; downloads are manual
  • Uncached Tesseract assets from jsDelivr

Captured pixels, recordings, Library entries, OCR results, and settings stay local. Translation and sharing happen only when invoked; update checks are automatic; uncached OCR assets may download as needed.

What stays on the device

Captures, recordings, Library entries and settings live under %APPDATA%\Capto. Recognition runs on-device with Tesseract in English plus the configured primary OCR language. On first use or a cache miss, its worker, core, or language assets may download from jsDelivr. Diagnostic logging is optional, off by default, and written locally when enabled.

Secrets

Translation API keys and cloud credentials are encrypted with Windows DPAPI and scoped to your user account. They are never written in plain text, and they are never sent anywhere except the provider they belong to.

Cloud share

Cloud share is opt-in. When you turn it on, Capto uploads to storage you configure — Cloudflare R2, Amazon S3, Tencent COS or Aliyun OSS — signing the request locally with your keys. Files live in your account. Uninstall Capto and every object remains yours.

Translation providers

The built-in keyless provider and any provider you add receive only the text you explicitly ask to translate. Supported providers are:

  • Built-in (keyless)
  • OpenAI
  • DeepSeek
  • OpenRouter
  • DeepL
  • Google Cloud Translation
  • A custom endpoint you supply

You bring those keys, and you can remove them at any time.

Automation URLs

The capto:// scheme is disabled until you enable it. While it is off, no external app can trigger a capture.

Updates

Capto checks trycapto.app for signed release metadata at startup and every 30 minutes. No capture content is included. Installer download begins only when you start it from the All-in-One command bar or Settings.

This website

The marketing site is static, sets no cookies, and runs no analytics. Inter is self-hosted; keycaps and code use the system monospace stack. The site makes no Google Fonts request.